Privacy Policy
This English version is provided for convenience. The German version is legally binding.
1. Controller
The controller responsible for data processing is:
Desislav Hristov
E-Mail: info@nocardio.fit
Tel.: +49 151 54290986
2. Principle
nocardio is free and ad-free – as a website and as an app for iOS and Android. We do not sell data and use no advertising tracking. We only process the data needed to operate the app. This policy applies to the website and to both apps; where something differs, that is stated explicitly.
3. Hosting (Vercel)
The website and the API used by the apps as well are hosted by Vercel Inc. When you access them, technically necessary server log data is processed (including IP address, time of request, requested resource, browser or app version). The legal basis is our legitimate interest in secure and stable operation (Art. 6 (1) (f) GDPR). A data processing agreement is in place with the provider.
4. Account and database (Supabase)
Account, training and body-weight data are stored with Supabase (processor pursuant to Art. 28 GDPR, EU region). The legal basis is the performance of the user relationship (Art. 6 (1) (b) GDPR).
5. Sign-in via Google
When signing in via Google, data is transmitted to and received from Google (name, email address, profile picture). The legal basis is the performance of the user relationship (Art. 6 (1) (b) GDPR).
6. What data we process for your account
We store the following categories for your account (this is also the content of the data export available in your profile):
- Account data: email address, time your account was created.
- Profile data: display name, optionally gender (for matching training templates), settings (theme, language, sound/vibration).
- Training data: plans, exercises, workout sessions, sets, weights, reps, duration.
- Body weight: the values you enter.
- Your own exercises: exercises you create, including your own images.
- Feedback: messages you send us via the feedback feature.
- AI analyses and AI imports: the results of your plan/statistics analyses and your plan imports (history, see section 12).
- Payments, if you have voluntarily supported us (see section 14).
7. Weight and training data as health-related data
Note, not conclusively reviewed: Body weight and training data (exercises, sets, weights, reps) may qualify as health data within the meaning of Art. 9 GDPR – a special category of personal data whose processing generally requires its own legal basis (usually your explicit consent, Art. 9 (2) (a) GDPR), not contract performance under Art. 6 (1) (b) GDPR alone. Whether and in what form such a separate, explicit consent must be obtained has not yet been conclusively clarified by a lawyer for nocardio and should be reviewed before this section is published. Regardless of the outcome of that review, the following already applies: we do not pass this data to third parties for advertising or analytics purposes, and you can view, correct or delete it at any time (section 16).
8. Camera access in the app
The app only requests your device's camera permission when you actively choose "Take photo" in an image picker – for your profile picture, a plan cover image, or the image of one of your own exercises. Without this permission you can still choose an existing image from your photo library; that requires no separate permission. Captured or selected images are only uploaded when you explicitly trigger it, and are then stored with Supabase (see section 4). The app does not access the camera at any other time or for any other purpose.
9. Notifications and device identifier
If you allow notifications in the app, we store a device identifier (a push token issued by Apple or Google) together with your account ID, the platform (iOS/Android) and the app version. This identifier belongs to the device, not permanently to a person – if a different account signs in on the same device, that account takes over the identifier. It is used exclusively to send you notifications about events originating outside your device (for example, the result of an AI analysis, a plan shared with you, or a service disruption notice) – not for advertising. Most of the app's reminders (e.g. rest timer end) are scheduled by your device itself, without transmitting anything to us. You can disable notifications at any time in your device's system settings or in your profile; deleting your account also removes the stored device identifier. The legal basis is your consent when you enable notifications (Art. 6 (1) (a) GDPR).
10. Local storage and offline operation
So nocardio also works without an internet connection, data is additionally stored locally on your device. What exactly is stored locally differs between the website and the app:
On the website (browser): Training data is additionally stored locally in your browser (IndexedDB/localStorage) and syncs once you are back online. This data remains on your device.
In the app (iOS/Android): In addition to the browser mechanism, the app stores in your device's internal, app-specific storage: the currently running workout document (so a checked-off set is preserved even if the app is closed and there is no connection), a queue of not-yet-transmitted entries (so sets recorded offline are not lost once a connection is available again), a local copy of exercise images (currently around 314 files – both from the app's own exercise library and images of your own exercises that you uploaded, so they can also be displayed offline), and your session token, which is stored there encrypted in the operating system's own keychain (iOS Keychain or Android Keystore) rather than in plain text.
None of this leaves your device, except when the app transmits it to our servers for synchronization. If you sign out, the app asks first if there is still untransmitted training data, and then removes the workout document, the session mirror and other local caches from that device; the same happens when you delete your account. The mirrored exercise images are pure app content with no personal reference and are unaffected by this.
11. Cookies
On the website, only technically necessary cookies are used (sign-in/session and your settings for theme and language). In the app, the on-device storage described in section 10 serves this function instead; a cookie banner is technically not applicable there. Neither the website nor the app perform any tracking. The legal basis is § 25 (2) TDDDG and Art. 6 (1) (f) GDPR.
12. AI services (Anthropic)
We use the AI service Anthropic (Claude), a company based in the USA, for two features:
- AI analysis of your plan or statistics: For this, we send Anthropic structured figures already computed from your training data – for example the exercises and sets of your plan, the weekly set volume per muscle group, or the number of workouts and volume trend of roughly the last 90 days. Your name or email address is not included.
- AI plan importer: For this, you yourself send photos, a PDF, or text of a training plan, which the AI converts into our plan format. Whatever is visible in those images or that document is sent to Anthropic to the extent you upload it.
The call is made exclusively server-side; the access key never resides in the browser or the app. We store the results in your account as described in section 6.
Note, not conclusively reviewed: Anthropic processes this data outside the EU. Whether and through which mechanism (e.g. EU Standard Contractual Clauses) this transfer is safeguarded under Art. 44 et seq. GDPR was not verified for this draft and should be confirmed before publication.
13. Quota limit for AI analyses
How many AI analyses you are entitled to within a rolling 30-day period also depends on whether you have voluntarily supported us (see Terms of Use, section 7, and section 14 below). For this we process the timestamps of your past AI analyses and, where applicable, your support payments.
14. Voluntary support (Stripe)
If you voluntarily support the app, you are redirected from the website to Stripe for payment processing (Stripe Payments Europe, Ltd.). The actual payment details (card number, IBAN and similar) are processed exclusively by Stripe; they never reach us. From the payment we receive and store: amount, date, currency and type (one-off or subscription), and, if provided, the email address on file with Stripe. We additionally store internally a technical copy of the event confirmation sent by Stripe, which – depending on the payment method chosen – may contain further details held by Stripe (such as name or billing address); this copy is used solely for troubleshooting payment matching, is never shown anywhere in the app, and is not part of your data export under section 6. The native app (iOS/Android) has no payment path; support is only possible via the website. This step is voluntary.
15. Storage period and deletion
We store your data as long as your account exists. You can delete your account at any time in your profile, which removes your account data as well as the local data described in section 10 on the device you are currently using.
16. Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability and objection (Art. 15–21 GDPR), as well as the right to lodge a complaint with a supervisory authority (Art. 77 GDPR).
17. Data security
Data is transmitted encrypted via HTTPS (TLS). Session data stored on the device is kept encrypted in the app in the operating system's own keychain (see section 10).
18. Updates
This privacy policy may be adjusted if the app or the legal situation changes.